CVE-2017-8288
Last modified
CVE-2017-8288 is a vulnerability of currently unknown severity. gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. EPSS estimates a 2.94% chance of exploitation in the next 30 days.
Description
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gnome-Shell | 3.22.0 |
| Gnome | Gnome-Shell | 3.22.1 |
| Gnome | Gnome-Shell | 3.22.2 |
| Gnome | Gnome-Shell | 3.22.3 |
| Gnome | Gnome-Shell | 3.23.1 |
| Gnome | Gnome-Shell | 3.23.2 |
| Gnome | Gnome-Shell | 3.23.3 |
| Gnome | Gnome-Shell | 3.23.90 |
| Gnome | Gnome-Shell | 3.23.91 |
| Gnome | Gnome-Shell | 3.23.92 |
| Gnome | Gnome-Shell | 3.24.0 |
| Gnome | Gnome-Shell | 3.24.1 |
References
- http://www.securityfocus.com/bid/98070Third Party Advisory, VDB Entry
- https://bugs.kali.org/view.php?id=2513Issue Tracking
- https://bugzilla.gnome.org/show_bug.cgi?id=781728Issue Tracking
- https://github.com/EasyScreenCast/EasyScreenCast/issues/46Third Party Advisory
- https://github.com/GNOME/gnome-shell/commit/ff425d1db7082e2755d2a405af53861552acf2a1Issue Tracking, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/98070Third Party Advisory, VDB Entry
- https://bugs.kali.org/view.php?id=2513Issue Tracking
- https://bugzilla.gnome.org/show_bug.cgi?id=781728Issue Tracking
- https://github.com/EasyScreenCast/EasyScreenCast/issues/46Third Party Advisory
- https://github.com/GNOME/gnome-shell/commit/ff425d1db7082e2755d2a405af53861552acf2a1Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8288?
How severe is CVE-2017-8288?
How do I fix CVE-2017-8288?
Are you affected by CVE-2017-8288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
